Aveva
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Aveva product.
RSS Feeds for Aveva security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Aveva products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Aveva Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 10 vulnerabilities in Aveva with an average score of 8.1 out of ten. Last year, in 2025 Aveva had 2 security vulnerabilities published. That is, 8 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.42.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 10 | 8.07 |
| 2025 | 2 | 7.65 |
| 2024 | 4 | 7.10 |
| 2023 | 12 | 7.78 |
| 2022 | 9 | 7.73 |
| 2021 | 7 | 7.54 |
| 2020 | 6 | 9.80 |
| 2019 | 3 | 8.70 |
| 2018 | 4 | 9.80 |
It may take a day or so for new Aveva vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Aveva Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-5387 | Apr 15, 2026 |
ICS: Privilege Escalation via Simulator Instructor/Developer AbuseThe vulnerability, if exploited, could allow an unauthenticated miscreant to perform operations intended only for Simulator Instructor or Simulator Developer (Administrator) roles, resulting in privilege escalation with potential for modification of simulation parameters, training configuration, and training records. |
|
| CVE-2026-1507 | Feb 10, 2026 |
Uncaught Exception in Core PI Services Allows Remote DaS (CVE-2026-1507)The affected products are vulnerable to an uncaught exception that could allow an unauthenticated attacker to remotely crash core PI services resulting in a denial-of-service. |
|
| CVE-2026-1495 | Feb 10, 2026 |
Event Log Reader Privilege Esc. to Leak Proxy CredentialsThe vulnerability, if exploited, could allow an attacker with Event Log Reader (S-1-5-32-573) privileges to obtain proxy details, including URL and proxy credentials, from the PI to CONNECT event log files. This could enable unauthorized access to the proxy server. |
|
| CVE-2025-64769 | Jan 16, 2026 |
Unencrypted Channels in Process Optimization Allow MITM AttacksThe Process Optimization application suite leverages connection channels/protocols that by-default are not encrypted and could become subject to hijacking or data leakage in certain man-in-the-middle or passive inspection scenarios. |
|
| CVE-2025-65117 | Jan 16, 2026 |
ICS: Process Optimization Designer Auth OLE Embed Priv EscThe vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Designer User) to embed OLE objects into graphics, and escalate their privileges to the identity of a victim user who subsequently interacts with the graphical elements. |
|
| CVE-2025-64729 | Jan 16, 2026 |
Auth User Escalates Priv via Code Inject in Proc Opt Project FilesThe vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to tamper with Process Optimization project files, embed code, and escalate their privileges to the identity of a victim user who subsequently interacts with the project files. |
|
| CVE-2025-65118 | Jan 16, 2026 |
ICS: Process Optimization Service Code Injection Elevates Privilege to SystemThe vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to trick Process Optimization services into loading arbitrary code and escalate privileges to OS System, potentially resulting in complete compromise of the Model Application Server. |
|
| CVE-2025-61943 | Jan 16, 2026 |
Captive Historian Auth Bypass Allows SQL Server Admin Code ExecThe vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Standard User) to tamper with queries in Captive Historian and achieve code execution under SQL Server administrative privileges, potentially resulting in complete compromise of the SQL Server. |
|
| CVE-2025-64691 | Jan 16, 2026 |
ICS: Authenticated User Escalates Privileges via TCL Macro TamperingThe vulnerability, if exploited, could allow an authenticated miscreant (OS standard user) to tamper with TCL Macro scripts and escalate privileges to OS system, potentially resulting in complete compromise of the model application server. |
|
| CVE-2025-61937 | Jan 16, 2026 |
taoimr RCE: Remote Code Execution under OS PrivilegesThe vulnerability, if exploited, could allow an unauthenticated miscreant to achieve remote code execution under OS system privileges of taoimr service, potentially resulting in complete compromise of the model application server. |
|
| CVE-2025-8386 | Nov 14, 2025 |
Appian Help Files XSS via aaConfigTools Enables PrivEscThe vulnerability, if exploited, could allow an authenticated miscreant (with privilege of "aaConfigTools") to tamper with App Objects' help files and persist a cross-site scripting (XSS) injection that when executed by a victim user, can result in horizontal or vertical escalation of privileges. The vulnerability can only be exploited during config-time operations within the IDE component of Application Server. Run-time components and operations are not affected. |
|
| CVE-2025-9317 | Nov 14, 2025 |
CVE-2025-9317: Edge Password Hash Bypass via Local File AccessThe vulnerability, if exploited, could allow a miscreant with read access to Edge Project files or Edge Offline Cache files to reverse engineer Edge users' app-native or Active Directory passwords through computational brute-forcing of weak hashes. |
|
| CVE-2024-3467 | Jun 12, 2024 |
AVeVA PI Asset Framework Client XML Import RCE via PI System ExplorerThere is a vulnerability in AVEVA PI Asset Framework Client that could allow malicious code to execute on the PI System Explorer environment under the privileges of an interactive user that was socially engineered to import XML supplied by an attacker. |
|
| CVE-2023-6132 | Feb 29, 2024 |
AVEVA Edge DLL Injection for Arbitrary Code Exec and Privilege EscalationThe vulnerability, if exploited, could allow a malicious entity with access to the file system to achieve arbitrary code execution and privilege escalation by tricking AVEVA Edge to load an unsafe DLL. |
|
| CVE-2023-31274 | Jan 18, 2024 |
Unauthenticated memory exhaustion DoS in AVEVA PI Server Message SubsystemAVEVA PI Server versions 2023 and 2018 SP3 P05 and prior contain a vulnerability that could allow an unauthenticated user to cause the PI Message Subsystem of a PI Server to consume available memory resulting in throttled processing of new PI Data Archive events and a partial denial-of-service condition. |
|
| CVE-2023-34348 | Jan 18, 2024 |
AVEVA PI Server 2023/2018 SP3 P05 Remote DoS via Unauthenticated CrashAVEVA PI Server versions 2023 and 2018 SP3 P05 and prior contain a vulnerability that could allow an unauthenticated user to remotely crash the PI Message Subsystem of a PI Server, resulting in a denial-of-service condition. |
|
| CVE-2021-42796 | Dec 16, 2023 |
CVE-2021-42796: AVEVA Edge ExecuteCommand UAC arbitrary command execAn issue was discovered in ExecuteCommand() in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior that allows unauthenticated arbitrary commands to be executed. |
|
| CVE-2021-42797 | Dec 16, 2023 |
Unauth Path Traversal in AVEVA Edge Enables Windows Token TheftPath traversal vulnerability in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior allows an unauthenticated user to steal the Windows access token of the user account configured for accessing external DB resources. |
|
| CVE-2021-42794 | Dec 16, 2023 |
AVEVA Edge connection string port scanning vulnerabilityAn issue was discovered in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior. The application allows a client to provide a malicious connection string that could allow an adversary to port scan the LAN, depending on the hosts' responses. |
|
| CVE-2023-33873 | Nov 15, 2023 |
Windows local OSauthenticated privilege escalation to SYSTEMThis privilege escalation vulnerability, if exploited, cloud allow a local OS-authenticated user with standard privileges to escalate to System privilege on the machine where these products are installed, resulting in complete compromise of the target machine. |
And others... |
| CVE-2023-34982 | Nov 15, 2023 |
OS Authentic User can Delete System Files via External Control VulnerabilityThis external control vulnerability, if exploited, could allow a local OS-authenticated user with standard privileges to delete files with System privilege on the machine where these products are installed, resulting in denial of service. |
And others... |
| CVE-2022-36969 | Mar 29, 2023 |
AVEVA Edge 2020 SP2 Patch 0 XXE in LoadImportedLibraries - Info DisclosureThis vulnerability allows remote attackers to disclose sensitive information on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000). User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the LoadImportedLibraries method. Due to the improper restriction of XML External Entity (XXE) references, a crafted document specifying a URI causes the XML parser to access the URI and embed the contents back into the XML document for further processing. An attacker can leverage this vulnerability to disclose information in the context of the current process. Was ZDI-CAN-17394. |
|
| CVE-2022-36970 | Mar 29, 2023 |
AVEVA Edge 20.0: RCE via crafted APP file (SP2)This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 20.0 Build: 4201.2111.1802.0000 Service Pack 2. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of APP files. Crafted data in a APP file can cause the application to execute arbitrary Visual Basic scripts. The user interface fails to provide sufficient indication of the hazard. An attacker can leverage this vulnerability to execute code in the context of current process. Was ZDI-CAN-17370. |
|
| CVE-2022-28685 | Mar 29, 2023 |
AVEdge 2020 SP2 4201.2111.1802.0000: APP File Deserialization Remote Code ExecThis vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000). User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of APP files. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-17212. |
|
| CVE-2022-28686 | Mar 29, 2023 |
AVEVA Edge 2020 SP2 Patch 0 RCE via unsecured APP file loadingThis vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000). User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of APP files. The process loads a library from an unsecured location. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-17114. |
|
| CVE-2022-28687 | Mar 29, 2023 |
AVEVA Edge 2020 SP2.Patch0 APP file lib load RCEThis vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000). User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of APP files. The process loads a library from an unsecured location. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16257. |
|
| CVE-2022-28688 | Mar 29, 2023 |
Remote Code Execution via APP Files before AVEVA Edge 2020 SP2 Patch 0This vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.0000). User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of APP files. The process loads a library from an unsecured location. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-17201. |
|
| CVE-2023-1256 | Mar 16, 2023 |
AVEVA Plant SCADA & Telemetry Server Improper Auth Remote Data LeakThe listed versions of AVEVA Plant SCADA and AVEVA Telemetry Server are vulnerable to an improper authorization exploit which could allow an unauthenticated user to remotely read data, cause denial of service, and tamper with alarm states. |
|
| CVE-2022-23854 | Dec 23, 2022 |
Path Traversal in AVEVA InTouch Access Anywhere Web ComponentAVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated user with network access to read files on the system outside of the secure gateway web server. |
|
| CVE-2021-38410 | Jul 27, 2022 |
AVEVA PCS Portal 4.5.2 DLL Hijacking via Uncontrolled PathAVEVA Software Platform Common Services (PCS) Portal versions 4.5.2, 4.5.1, 4.5.0, and 4.4.6 are vulnerable to DLL hijacking through an uncontrolled search path element, which may allow an attacker control to one or more locations in the search path. |
And others... |
| CVE-2022-1467 | May 23, 2022 |
Windows OS can be configured to overlay a language bar on top of any applicationWindows OS can be configured to overlay a language bar on top of any application. When this OS functionality is enabled, the OS language bar UI will be viewable in the browser alongside the AVEVA InTouch Access Anywhere and Plant SCADA Access Anywhere applications. It is possible to manipulate the Windows OS language bar to launch an OS command prompt, resulting in a context-escape from application into OS. |
|
| CVE-2022-0835 | Apr 11, 2022 |
AVEVA System Platform 2020 stores sensitive information in cleartext, which mayAVEVA System Platform 2020 stores sensitive information in cleartext, which may allow access to an attacker or a low-privileged user. |
|
| CVE-2021-32977 | Apr 04, 2022 |
AVEVA System Platform versions 2017 through 2020 R2 P01 does not verifyAVEVA System Platform versions 2017 through 2020 R2 P01 does not verify, or incorrectly verifies, the cryptographic signature for data. |
|
| CVE-2021-32981 | Apr 04, 2022 |
AVEVA System Platform versions 2017 through 2020 R2 P01 uses external input to construct a pathnameAVEVA System Platform versions 2017 through 2020 R2 P01 uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the software does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory. |
|
| CVE-2021-32985 | Apr 04, 2022 |
AVEVA System Platform versions 2017 through 2020 R2 P01 does not properly verifyAVEVA System Platform versions 2017 through 2020 R2 P01 does not properly verify that the source of data or communication is valid. |
|
| CVE-2021-33008 | Apr 04, 2022 |
AVEVA System Platform versions 2017 through 2020 R2 P01 does not perform any authentication for functionalityAVEVA System Platform versions 2017 through 2020 R2 P01 does not perform any authentication for functionality that requires a provable user identity. |
|
| CVE-2021-33010 | Apr 04, 2022 |
An exception is thrownAn exception is thrown from a function in AVEVA System Platform versions 2017 through 2020 R2 P01, but it is not caught, which may cause a denial-of-service condition. |
|
| CVE-2021-32987 | Sep 23, 2021 |
Null pointer dereference in SuiteLink server while processing command 0x0bNull pointer dereference in SuiteLink server while processing command 0x0b |
|
| CVE-2021-32959 | Sep 23, 2021 |
Heap-based buffer overflow in SuiteLink server while processing commands 0x05/0x06Heap-based buffer overflow in SuiteLink server while processing commands 0x05/0x06 |
|
| CVE-2021-32999 | Sep 23, 2021 |
Improper handling of exceptional conditions in SuiteLink server while processing command 0x01Improper handling of exceptional conditions in SuiteLink server while processing command 0x01 |
|
| CVE-2021-32979 | Sep 23, 2021 |
Null pointer dereference in SuiteLink server while processing commands 0x04/0x0aNull pointer dereference in SuiteLink server while processing commands 0x04/0x0a |
|
| CVE-2021-32971 | Sep 23, 2021 |
Null pointer dereference in SuiteLink server while processing command 0x07Null pointer dereference in SuiteLink server while processing command 0x07 |
|
| CVE-2021-32963 | Sep 23, 2021 |
Null pointer dereference in SuiteLink server while processing commands 0x03/0x10Null pointer dereference in SuiteLink server while processing commands 0x03/0x10 |
|
| CVE-2021-32942 | Jun 09, 2021 |
The vulnerability could expose cleartext credentialsThe vulnerability could expose cleartext credentials from AVEVA InTouch Runtime 2020 R2 and all prior versions (WindowViewer) if an authorized, privileged user creates a diagnostic memory dump of the process and saves it to a non-protected location. |
|
| CVE-2020-13499 | Sep 24, 2020 |
An SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053An SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053. Specially crafted SOAP web requests can cause SQL injections resulting in data compromise. Parameter InstancePath in CHaD.asmx is vulnerable to unauthenticated SQL injection attacks. |
|
| CVE-2020-13500 | Sep 24, 2020 |
SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053. Specially crafted SOAP web requests can cause SQL injections resulting in data compromise. Parameter ClassName in CHaD.asmx is vulnerable to unauthenticated SQL injection attacks. |
|
| CVE-2020-13501 | Sep 24, 2020 |
An SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053An SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053. Specially crafted SOAP web requests can cause SQL injections resulting in data compromise. Parameter InstanceName in CHaD.asmx is vulnerable to unauthenticated SQL injection attacks. |
|
| CVE-2020-13504 | Sep 24, 2020 |
Parameter AttFilterValue in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacksParameter AttFilterValue in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks. Specially crafted SOAP web requests can cause SQL injections resulting in data compromise. An attacker can send unauthenticated HTTP requests to trigger this vulnerability. |
|
| CVE-2020-13505 | Sep 24, 2020 |
Parameter psClass in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacksParameter psClass in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks. Specially crafted SOAP web requests can cause SQL injections resulting in data compromise. An attacker can send unauthenticated HTTP requests to trigger this vulnerability. |
|
| CVE-2019-13537 | Jan 14, 2020 |
The IEC870IP driver for AVEVAs Vijeo Citect and Citect SCADA and Schneider Electrics Power SCADA Operation has a buffer overflow vulnerabilityThe IEC870IP driver for AVEVAs Vijeo Citect and Citect SCADA and Schneider Electrics Power SCADA Operation has a buffer overflow vulnerability that could result in a server-side crash. |